Under HIPAA, a business associate is any person or organization outside a covered entity’s workforce that creates, receives, maintains, or transmits protected health information while performing work for that covered entity. The definition sits at 45 CFR § 160.103 and sweeps in a wide range of vendors, contractors, and professional service firms whose work touches patient data. Getting the classification right matters: a covered entity that shares patient information with a vendor without a written business associate agreement in place has violated HIPAA even if no breach ever occurs, and since the HITECH Act of 2009 the vendors themselves are directly liable to federal regulators for their own violations.145 CFR § 160.103
The Two Paths in the Regulation
An entity becomes a business associate through one of two routes, and either one is enough.
The first route covers anyone who handles protected health information while carrying out a regulated function on behalf of a covered entity. The regulation lists activities like claims processing, data analysis, utilization review, benefits management, billing, and practice management. The phrase that does the work here is “on behalf of.” The vendor has to be performing a job the covered entity would otherwise do itself or is responsible for.
The second route covers professional service providers whose work for a covered entity involves access to protected health information. The regulation specifically names legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation, and financial services.
Both routes share a threshold: the entity must sit outside the covered entity’s workforce. Employees, trainees, and volunteers acting under a covered entity’s direct control are governed by that entity’s own HIPAA policies, not by business associate rules.
Covered entities, for reference, are the healthcare providers who transmit health information electronically for standard transactions, health plans including Medicare and Medicaid, and healthcare clearinghouses. When one of them hands work to an outsider that involves patient data, the business associate question comes up.
Common Examples
The category is broader than most organizations realize. Third-party administrators and pharmacy benefit managers move enormous volumes of patient data for health plans and almost always qualify. Cloud storage providers that host electronic medical records qualify even if nobody at the cloud company ever opens a file — simply storing the data is enough. Medical billing companies that handle claims containing diagnosis codes and treatment details fall squarely inside the definition.
Law firms representing hospitals in malpractice or contract matters routinely review patient records, and they become business associates for those engagements. IT contractors that maintain or can access electronic health record systems qualify. So do shredding companies hired to destroy paper records with patient information, and consultants brought in for quality assurance or accreditation work that requires access to charts.
Subcontractors Count Too
One point trips up organizations that assume the rule stops at the first vendor. If a business associate hires another firm to help with work involving protected health information, that subcontractor is itself a business associate and carries the same obligations. The regulation at 45 CFR § 160.103 says this directly, and the business associate agreement between the covered entity and its associate has to require the associate to bind any subcontractors to the same restrictions.145 CFR § 160.103 A cloud provider used by a billing company that serves a hospital is a business associate. So is the data center the cloud provider leases from, if that data center can access the information.
Who Is Not a Business Associate
Several categories of people and organizations touch medical data without falling under the definition, and knowing the exclusions matters as much as knowing the rule.
Healthcare providers receiving patient information for treatment are excluded. A hospital referring a patient to a specialist and sending the chart along does not need a business associate agreement with that specialist. A physician sending lab samples and patient data to a laboratory is in the same position. Provider-to-provider treatment disclosures are not vendor relationships.
Entities whose contact with protected health information is incidental to the actual service they provide are also outside the definition. The U.S. Postal Service, private couriers, and internet service providers are the standard examples. They move data but do not access or use it in any meaningful way. HHS has described the test as whether the entity’s functions “do not involve the use or disclosure of protected health information, and where any access to protected health information by such persons would be incidental, if at all.”
Plan sponsors that receive enrollment information from a group health plan sit outside the definition to the extent they comply with the separate disclosure limits at 45 CFR § 164.504(f).245 CFR § 164.504(f) Government agencies determining eligibility for public health programs are excluded when they act under legal authority.
And an entity that receives only de-identified information is not a business associate with respect to that data. De-identified information is not protected health information under HIPAA, so no business associate obligations attach. The identifiers have to be stripped to the point where there is no reasonable basis to identify any individual.
Why the Classification Matters
Once someone qualifies as a business associate, three things follow.
First, the covered entity has to put a written business associate agreement in place before any protected health information changes hands. The required contents are set out at 45 CFR § 164.504(e), and the contract must define permitted uses, require appropriate safeguards, mandate breach reporting, flow the same obligations down to subcontractors, support patient rights requests, open the associate’s records to HHS for audit, and address return or destruction of data when the relationship ends.345 CFR § 164.504(e) Operating without this agreement is itself a violation.
Second, the business associate has direct compliance duties of its own. The HITECH Act of 2009 made associates directly liable under the HIPAA Security Rule, meaning they must independently implement the administrative, physical, and technical safeguards at 45 CFR §§ 164.308, 164.310, 164.312, and 164.316, starting with a risk analysis of the electronic protected health information they hold.445 CFR § 164.308(a)(1)(ii)(A) They also have to report breaches of unsecured protected health information to the covered entity, with an outer limit of 60 calendar days after discovery under 45 CFR § 164.410, though many business associate agreements set shorter deadlines.545 CFR § 164.410
Third, enforcement runs directly against the business associate. HHS’s Office for Civil Rights can investigate complaints, conduct audits, and impose civil monetary penalties on the associate without the covered entity being involved. Penalty tiers run from a floor of $145 per violation for no-knowledge cases up to $2,190,294 per violation for willful neglect left uncorrected, with a calendar-year cap of $2,190,294 for repeated violations of the same provision in 2026. Separate provisions carry separate caps, so exposure for an organization with multiple compliance failures can climb well above the single-provision figure.
The practical takeaway is straightforward: if an outside vendor will create, receive, maintain, or transmit patient information for a covered entity, and the relationship does not fit one of the specific exclusions, that vendor is a business associate. The label triggers a written contract, a set of direct federal obligations for the vendor, and enforcement authority that reaches both sides of the arrangement.